libgadu: Multiple vulnerabilities
Multiple vulnerabilities have been found in libgadu, the worst of
which may result in execution of arbitrary code.
libgadu
2015-08-15
2015-08-15
490238
505558
510714
remote
1.12.0
1.12.0
libgadu is a library that implements the client side of the Gadu-Gadu
protocol.
libgadu contains multiple vulnerabilities:
- X.509 certificates are not properly validated (CVE-2013-4488)
- A integer overflow error could lead to a buffer overflow
(CVE-2013-6487)
- Malformed responses from a Gadu-Gadu file relay server are not
properly handled (CVE-2014-3775)
A remote attacker may be able to execute arbitrary code with the
privileges of the process, cause a Denial of Service condition, or spoof
servers.
There is no known workaround at this time.
All libgadu users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-libs/libgadu-1.12.0"
CVE-2013-4488
CVE-2013-6487
CVE-2014-3775
BlueKnight
ackle